Skip to main content
Enterprise SecurityLast updated: August 21, 2026

Trust & Security Center

Enterprise-grade data protection, cryptographic secret isolation, and human-in-the-loop agent governance.

1. Zero Customer Data Training

Your data is strictly yours. Operon does not train foundational AI models on your workspace goals, uploaded artifacts, custom prompt instructions, or tool execution history.

  • All upstream model integrations (OpenAI, Anthropic, Google Vertex AI, Groq) are configured via enterprise zero-data-retention APIs where customer inputs are never used to train public models.
  • When you utilize Bring Your Own Key (BYOK), requests execute under your direct organization agreement with each model provider.

2. Encrypted BYOK Vault Architecture

When you add proprietary API keys (OpenAI, Anthropic, Google Gemini, Groq, or custom REST secrets) to Operon, they are never stored in plaintext.

  • Two-Tier Envelope Encryption: Secrets are encrypted using individual Data Encryption Keys (DEKs) wrapped by an AES-256 Fernet Master Key.
  • Ephemeral Memory Ingestion: Keys are decrypted exclusively in worker RAM during execution turns and immediately flushed upon step completion.
  • Zero Log Exposure: Automated log scrubbers sanitize all API keys, PATs, and bearer tokens before payloads enter application logs or Sentry telemetry.

3. Multi-Tenant Data Isolation

Operon employs strict row-level security and tenant-scoped schema policies. Every database query, vector semantic search in pgvector, artifact file retrieval, and WebSocket streaming channel is bounded to verified organization IDs issued by Clerk JWT authentication.

4. Sandboxed Tool & SQL Guardrails

Autonomous agents operate within defense-in-depth boundaries to prevent unauthorized operations:

  • Read-Only SQL AST Sanitization: Database query tools inspect SQL syntax trees to enforce read-only (SELECT) operations, rejecting DROP, UPDATE, DELETE, or ALTER statements.
  • Human-In-The-Loop (HITL) Interrupts: High-risk operations (such as sending emails, deleting repositories, or public publishing) automatically pause execution and require explicit approval in your Inbox.
  • Workspace Sandboxing: File operations are sandboxed within tenant-isolated storage buckets with strict path traversal prevention.

5. Prompt Injection Defense & Input Screening

Operon deploys continuous prompt guardrails to detect and mitigate indirect prompt injections from untrusted web pages, emails, or third-party API outputs before they can influence agent planning decisions.

6. SOC2, ISO & Enterprise Governance

Operon adheres to SOC2 Type II trust service principles covering Security, Availability, and Confidentiality. We maintain immutable audit logs (AuditEvent) capturing actor IDs, execution durations, IP addresses, and resource access for enterprise compliance.

Download our compliance documentation or request a custom DPA on our Data Processing Agreement page.

7. Responsible Vulnerability Disclosures

We welcome collaboration with security researchers. If you discover a potential vulnerability in Operon, please report it responsibly to security@operon.ai. We commit to acknowledging receipt within 24 hours and providing remediation updates.